Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-14350NoneMalicious code in scrambleeer (PyPI)
Malicious code in scrambleeer (PyPI)
MAL-2026-14349NoneMalicious code in boto4 (PyPI)
Malicious code in boto4 (PyPI)
MAL-2026-14341NoneMalicious code in reqcrypts (PyPI)
Malicious code in reqcrypts (PyPI)
CVE-2026-54457High· 7.7TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied…
CVE-2026-43980Medium· 6.3Malla is a web analyzer for Meshtastic networks based on MQTT data
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered int…
CVE-2026-49360HighRecce is a data-validation toolkit for enhanced dbt (data build tool) PR review
Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL …
CVE-2026-35163MediumOctoPrint provides a web interface for controlling consumer 3D printers
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/…
CVE-2026-71428Critical· 9.3The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…
CVE-2026-72818High· 7.5PoCThe URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Inpu…
CVE-2026-71492Medium· 6.5Banks generates meaningful LLM prompts using a simple template language
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…
CVE-2026-55558Medium· 5.9aiosmtplib is an asynchronous SMTP client for use with asyncio
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. A…
CVE-2026-54770Medium· 6.1WebOb provides objects for HTTP requests and responses
WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…
CVE-2026-54623High· 7.1django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value with…
CVE-2026-54625Medium· 4.8django CMS is a content management system powered by Django
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key funct…
GHSA-5p3m-vhh6-9236Medium· 6.3stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
GHSA-jgvr-6x5w-hx5wMediumZoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
GHSA-mc9m-6fm9-pghcMediumZoo Design Studio: Memory-corruption in memory handling of lib-kcl
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
CVE-2026-54259Medium· 4.3Wagtail: Improper restriction handling on Documents and Images chosen endpoints
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVE-2026-54260Medium· 4.3Wagtail: Denial of service via unbounded filter specs in the image preview
Wagtail: Denial of service via unbounded filter specs in the image preview
CVE-2026-54261Medium· 6.5Wagtail: Improper permission handling in image preview
Wagtail: Improper permission handling in image preview
CVE-2026-54262Medium· 4.3Wagtail: Pages translations can be created without page permissions when using simple_translation
Wagtail: Pages translations can be created without page permissions when using simple_translation
CVE-2026-54263High· 7.3Wagtail: Reflected XSS in dynamic image URL generator view
Wagtail: Reflected XSS in dynamic image URL generator view
CVE-2026-54622Medium· 6.5django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
CVE-2026-54624Medium· 6.5django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
CVE-2026-55468Medium· 4.3Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API
CVE-2026-75526Medium· 4.4django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values…
CVE-2026-63003Medium· 6.5django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePa…
CVE-2026-61663Medium· 4.3django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
GHSA-92hv-j533-69wcLow· 3.7Wagtail: Identification of documents by SHA1 hash
Wagtail: Identification of documents by SHA1 hash
GHSA-c2xx-cjmh-9q8fMedium· 5.3Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Wagtail: Improper restriction handling on descendant collections in Documents and Images API